Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

What does an insider mean now that AI agents and OAuth apps count?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20026
Topic starter  

TL;DR: Insider risk definitions built around employees and contractors no longer match the 2026 identity surface, according to Above’s analysis. AI agents, OAuth-connected apps, and lingering third-party access now sit inside the same harm model, which means program scope, ownership, and review processes must expand beyond Workday-era assumptions.

NHIMG editorial — based on content published by Above: What "Insider" Actually Means in 2026 and Why the Definition I Used as a CISO No Longer Holds

Questions worth separating out

Q: What breaks when an insider programme only tracks employees and contractors?

A: It misses the identities that now create real exposure outside HR records, especially service accounts, OAuth apps, and AI agents.

Q: Why do OAuth-connected third-party apps create identity risk?

A: OAuth-connected apps extend trust beyond the organisation’s own perimeter into a vendor’s security posture.

Q: How should security teams govern AI-powered insider threats?

A: Treat AI-powered insider threat as an identity governance problem first.

Practitioner guidance

  • Recast the insider definition Update the programme charter so it explicitly covers humans, service accounts, OAuth apps, and autonomous agents that hold authorised access and can cause harm.
  • Inventory non-human identities inside the insider programme Build a complete register of delegated apps, machine identities, and agent accounts that currently sit outside HR-driven data models.
  • Bind access reviews to identity lifecycle events Trigger recertification and revocation reviews when an app, agent, or service account changes purpose, ownership, or integration scope.

What's in the full article

Above's full blog post covers the operational detail this post intentionally leaves for the source:

  • The article’s original breakdown of how the insider definition evolved from a human roster model into a broader identity model.
  • The full discussion of AI agents, OAuth-connected apps, and third-party relationships as part of the insider surface.
  • The author’s own working draft of a 2026 insider definition and the governance questions it raises for CISOs.
  • The article’s closing prompt set for insider charter reviews and ownership alignment.

👉 Read Above's analysis of why the insider definition no longer fits 2026 →

What does an insider mean now that AI agents and OAuth apps count?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19617
 

Insider risk is now an identity-classification problem, not just a behaviour problem. The working definition of insider determines what the programme sees, measures, and governs. If the definition stops at employees and contractors, every non-human identity with authorised access remains outside the risk model even when it can cause equivalent or greater harm. The practitioner conclusion is simple: insider scope has to follow identity type, not org chart assumptions.

A few things that frame the scale:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, according to The State of Non-Human Identity Security.
  • A second finding in the same study shows that 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, with 38% reporting no or low visibility.

A question worth separating out:

Q: Should organisations expand insider risk ownership beyond security?

A: Yes. If insider risk now includes human identities, delegated apps, service accounts, and agents, then no single team owns the whole problem. Security may coordinate the policy, but IAM, application owners, HR, legal, and business leaders all own pieces of the lifecycle and the approvals that make the access real.

👉 Read our full editorial: Insider definitions are failing as AI agents and OAuth apps join the scope



   
ReplyQuote
Share: